GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)

GigaWiper: Multi-Stage Destructive Windows Backdoor (TL-2026-1167), also tracked as BLUERABBIT, is a high-severity malware campaign, first published 2026-07-10. It is attributed to CyberAv3ngers lineage (Iran) with low confidence, affects Microsoft Windows (all supported client and server versions with a, maps to 33 MITRE ATT&CK techniques (T1007, T1012, T1016), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-1167

Threat ID
TL-2026-1167
Also known as
BLUERABBIT
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-10
Last reviewed
2026-07-10
Attribution
CyberAv3ngers lineage
Attribution confidence
LOW
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
critical infrastructure, water, energy, unspecified broad windows targeting per microsoft
Target regions
israel, united states of america, united kingdom, ireland
Detection rules
9
Indicators of compromise
28

Malware and tooling in GigaWiper: Multi-Stage Destructive Windows Backdoor

Malware and tooling: Crucio, CutBrooch, FlockWiper, GigaWiper, MinIO client, RabbitMQ (AMQP), Redis

GigaWiper is a Golang-based Windows backdoor first observed by Microsoft in October 2025 that consolidates a standalone raw-disk wiper, Crucio-derived fake-ransomware encryption (.candy extension, no retained keys), and a reimplemented FlockWiper multi-pass wiper into a single 20-command RabbitMQ/Redis-tasked platform alongside VNC-style remote control, screen surveillance, and event-log wiping. Binary Defense independently tracked the same file set as BLUERABBIT in March 2026 and assesses an Iran-nexus actor (Crucio/CyberAv3ngers lineage) targeting Israeli organizations.

How GigaWiper: Multi-Stage Destructive Windows Backdoor works

GigaWiper is a modular, Golang-compiled Windows backdoor that Microsoft Threat Intelligence disclosed on July 9, 2026, tracing destructive wiping incidents back to October 2025. Unlike single-purpose wipers, GigaWiper is architected as a full command-and-control implant with 20 distinct operator commands spanning destructive, reconnaissance, and surveillance categories, delivered over a RabbitMQ message broker (AMQP, fanout exchange "All" for broadcast and topic exchange "Topic" for targeted routing-key tasking) with results and output returned via Redis as a structured cmd.Result object (error, target_ip, task_id, computer_name, output, pwd, time, status, work_status).

The malware establishes persistence by using PowerShell to register a scheduled task named "OneDrive Update" that runs at both system startup and on a one-minute interval, masquerading as legitimate OneDrive telemetry. A registry value at HKCU\SOFTWARE\OneDrive\Environment tracks execution count to prevent redundant re-initialization.

Destructive capability is delivered through three related-but-distinct code paths that Microsoft assesses were authored by the same developer(s) and stitched together into GigaWiper:

1. Command 1 (WipeMain) performs physical-disk-level destruction: it enumerates physical drives via WMI (Win32_DiskDrive), identifies which drive hosts the Windows installation, strips partition references from the remaining drives via IOCTL_DISK_CREATE_DISK (DeviceIoControl), overwrites raw disk content in 10MB (0xA00000-byte) chunks with a crypto/rand-randomized first byte followed by zero-fill, and forces an immediate, zero-delay reboot. 2. Command 12 (WipeCMain) is a reimplementation of the standalone FlockWiper C tool (first seen on VirusTotal in June 2025, PDB path A:\GRAT\CWipeNew\Release\CWipeNew.pdb) — a multi-pass secure wipe of the Windows installation drive specifically, cycling through 0x00, 0xFF, and random byte patterns with pass-timing telemetry. 3. Command 3 (RanMain / BigBangExtortMain) is fake ransomware whose function name and logic Microsoft matched to the Crucio ransomware family documented in a December 2023 CISA advisory on IRGC-affiliated actors exploiting PLCs (the same lineage publicly tied to CyberAv3ngers water/energy-sector intrusions in the US, UK, and Ireland). It generates a random AES-CBC key/IV that is never persisted anywhere, encrypts files (excluding .exe/.dll), appends a .candy extension, deletes the plaintext originals, and drops a wallpaper image (image_danger.jpg) — producing ransomware-style victim messaging with zero possibility of recovery since no key exists to recover.

Command 2 triggers a BSOD via boot-file deletion; Command 19 wipes System, Setup, Application, Security, and ForwardedEvents Windows Event Logs via `wevutil clear-log`, falling back to direct deletion of C:\Windows\System32\winevt\Logs\Security.evtx if the utility call fails — clearing forensic evidence ahead of or during destructive operations.

Beyond destruction, GigaWiper functions as a full-featured espionage/RAT platform: Command 9 captures per-monitor screenshots; Command 10 records the screen opportunistically when the session is unlocked and the user has been active for more than 10 seconds; Command 20 opens a direct TCP listener providing VNC-like live remote desktop control (screen streaming plus keyboard/mouse injection), protected by a firewall rule deceptively named after the legitimate Windows component "Microsoft.Windows.CloudExperienceHost"; Command 7 executes arbitrary PowerShell with persistent working-directory state; Command 15 collects system information (IP, CPU, OS, and installed antivirus products enumerated via `Get-WmiObject -Namespace root\SecurityCenter2`); Commands 16-18 provide full process, service, and interactive registry management; Command 5 performs bulk AES-256-CBC file encryption/decryption with attacker-supplied keys (a legitimate-use variant of the ransomware primitive); Command 4 exfiltrates files to attacker-controlled storage via a MinIO client; Command 8 manages RabbitMQ Topic-exchange routing-key bindings for individually targeted tasking; and Commands 6/11/13/14 are unused placeholder structures suggesting additional wiper/keylogger modules exist but were not recovered in analyzed samples.

Unstripped GigaWiper PE binaries allowed Microsoft to recover Golang package/function names (rabbit_tools_*, rabbit_bin, cmd_* modules) and identify the recurring debug string "GRAT" across both GigaWiper and FlockWiper artifacts, indicating a shared, still partially unidentified development framework and a probable single threat-actor lineage spanning Crucio (2023), FlockWiper (June 2025), and GigaWiper (October 2025-present).

Microsoft's public blog does not assign country attribution, but independent researcher Binary Defense tracked identical files as "BLUERABBIT" starting March 2026 and assesses an Iran-nexus actor targeting Israeli organizations, consistent with the historical CyberAv3ngers/IRGC-linked Crucio lineage against critical infrastructure. Observed C2 infrastructure: 185.182.193[.]21 (RabbitMQ on TCP/5544, Redis on TCP/7542) with 212.8.248[.]104 as apparent backup/secondary C2.

Microsoft Defender AV/EDR detects the family under Giga, Wiper, FlockWiper, and CutBrooch naming, with behavioral detections WprFlock and WprCree, and has published a Threat Analytics "Tool profile: GigaWiper" report. Recommended mitigations focus on tamper protection (blocking AV/EDR disablement and exclusion changes), disabling GPO-based local-admin AV exclusion merges, cloud-delivered protection, EDR in block mode, and attack-surface-reduction rules blocking unsigned/low-prevalence executables — alongside treating any confirmed GigaWiper intrusion as a business-continuity emergency requiring immediate isolation, backup verification, and C2 blocking before destructive commands can propagate.

MITRE ATT&CK techniques used in TL-2026-1167

Discovery

T1007 System Service Discovery; T1012 Query Registry; T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery; T1518 Software Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1053 Scheduled Task/Job

Credential Access

T1056 Input Capture

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1569 System Services

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Collection

T1074 Data Staged; T1113 Screen Capture

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1491 Defacement; T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot; T1561 Disk Wipe

Affected products and versions in GigaWiper: Multi-Stage Destructive Windows Backdoor

  • Microsoft — Windows (all supported client and server versions with a physical or virtual disk)
    Vulnerable versions: Windows 10; Windows 11; Windows Server

Remediation for GigaWiper: Multi-Stage Destructive Windows Backdoor

Immediate actions

  • Block C2 IPs 185.182.193[.]21 and 212.8.248[.]104 (RabbitMQ TCP/5544, Redis TCP/7542) at perimeter and DNS/egress firewalls
  • Isolate any host running a scheduled task named 'OneDrive Update' or with HKCU\SOFTWARE\OneDrive\Environment registry value present
  • Preserve forensic evidence and verify offline/immutable backups before further triage — treat as a business-continuity emergency
  • Hunt for wevutil clear-log invocations against System/Setup/Application/Security/ForwardedEvents logs and for direct deletion of Security.evtx
  • Restrict local administrator rights to prevent tamper-protection bypass and antivirus exclusion changes

Workarounds

  • Block outbound AMQP (5672 and non-standard RabbitMQ ports) and Redis (6379 and non-standard ports) to unrecognized external hosts
  • Alert on scheduled tasks created via PowerShell with minute-interval triggers disguised as update tasks

Longer-term hardening

  • Deploy EDR with behavioral detection tuned for WprFlock/WprCree/FlockWiper/GigaWiper signatures
  • Enable Microsoft Defender Tamper Protection and disable GPO-based local-admin AV-exclusion merge (DisableLocalAdminMerge)
  • Enable Attack Surface Reduction rules blocking execution of unsigned/low-prevalence/low-age executables
  • Enable Automated Investigation and Remediation and EDR in block mode
  • Implement offline/immutable, air-gapped backup strategy resilient to full-disk wipe scenarios
  • Monitor for firewall rules masquerading as legitimate Windows components (e.g., 'Microsoft.Windows.CloudExperienceHost')

Weaknesses (CWE) in GigaWiper: Multi-Stage Destructive Windows Backdoor

CWE-506, CWE-311, CWE-778

Timeline of GigaWiper: Multi-Stage Destructive Windows Backdoor

  • CISA publishes joint advisory AA23-335A on IRGC-affiliated cyber actors (CyberAv3ngers) exploiting internet-exposed PLCs at water/wastewater facilities; documents the Crucio ransomware family whose BigBangExtortMain encryption logic later appears verbatim in GigaWiper Command 3
  • FlockWiper, a standalone C-based multi-pass Windows-drive wiper carrying the 'GRAT' PDB debug string (A:\GRAT\CWipeNew\Release\CWipeNew.pdb), is first uploaded to VirusTotal — its wiping logic is later reimplemented as GigaWiper Command 12 (WipeCMain)
  • Microsoft Threat Intelligence first observes Windows environments being wiped, marking the earliest documented destructive GigaWiper activity
  • Binary Defense independently identifies the same file set under the name BLUERABBIT, assessing an Iran-nexus actor targeting Israeli organizations
  • The Hacker News, SC Media, Cyberpress, Security Affairs, and Hackread publish independent coverage summarizing Microsoft's findings and amplifying IOCs
  • Microsoft Defender Threat Analytics concurrently publishes a 'Tool profile: GigaWiper' report, adding Defender detection naming (Giga, Wiper, FlockWiper, CutBrooch) and behavioral detections (WprFlock, WprCree) for defender consumption
  • Microsoft publishes 'GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware,' detailing the 20-command RabbitMQ/Redis backdoor architecture, unstripped-binary Golang package/function-name recovery, IOCs, and detection guidance
  • Cyber Security News publishes a technical summary article covering GigaWiper's disk-wiping, encryption, and boot-sabotage capabilities, prompting hunt intake into this pipeline

Sources cited for GigaWiper: Multi-Stage Destructive Windows Backdoor

Threats related to GigaWiper: Multi-Stage Destructive Windows Backdoor

Detection coverage for TL-2026-1167

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1167 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1167

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats